Beveiligingsadvies

CVE-2015-7675

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-02-10 15:00:00
Laatst bijgewerkt 2024-08-06 07:58:59
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.